Skip to content
← Back

Privacy & COPPA posture

Plain English. Last updated June 2026.

Who this is for

FamSpots is operated by parents and guardians who are 18 or older. Kids do not have their own accounts, cannot log in, cannot post anything, and cannot chat with anyone. By creating an account you confirm you're the parent or legal guardian of any child whose profile you add. See our Terms of Service.

Alias-first by design

We're intentionally alias-first: grown-ups pick a playful handle (Captain Mom, Trail Lead) and kids get code-name nicknames (Zippy Fox, Cosmic Otter). We never ask for real names, and the app nudges you toward an alias if what you type looks like one. This isn't anonymity — we still store your sign-in email, the places you save, and your approximate location when you ask "What now?" (see below) — but keeping real names out of the system meaningfully reduces what a worst-case breach could reveal about your family. You can edit, export, or delete your profile at any time.

What we store

  • The signed-in parent's email (from sign-in).
  • The family profile you entered: kid nicknames (not full names), ages, dietary needs, food likes/dislikes, interests, accessibility/sensory needs, and your travel preferences.
  • Places you favorited or recently picked (place id, name, address, timestamp), so the Saved tab works across devices.
  • A daily counter of how many external API calls your account has made, so we can enforce a fair-use ceiling.

We do not store: kids' real names, photos, birthdates, contact info, school, exact home address, browsing behavior, or any data from third-party trackers. There are no ad SDKs and no analytics that identify you personally.

What happens with your location and queries

When you ask "What now?" your browser shares your device location with the app to find nearby places. Before we call Google's Places API, we snap that location to a coarse grid (roughly one mile across) — Google never receives your exact coordinates, and neither does our database. The precise reading exists only in memory for the length of that single request, long enough to sort the returned places by distance, and is then discarded. We never write your coordinates to your account, to logs, or to analytics. Under California's CPRA definition of "precise geolocation" (finer than ~1,850 ft / 564 m), the location we work with is not precise geolocation.

We may also send a short prompt to an AI provider to write a one-line rationale for a pick. That prompt contains the place name and matching factors — never your kids' nicknames, ages, or identifying details verbatim.

To keep costs down and results fast, we cache Google's responses about places(not about you) in a shared cache keyed by that same coarse grid cell and query — so future searches in the same neighborhood are served without re-querying Google. That cache contains no user identifiers and is never joined back to individual accounts.

Cookies and local storage

FamSpots does not set non-essential cookies. We keep your sign-in session and app preferences (such as local vs. travel mode) in your browser's local storage, not in cookies. Our analytics provider, DataFast, is cookieless and does not fingerprint you. The only third-party cookies you may encounter are set by Google Maps when you use the map on the Explore page, which is standard for embedded map functionality.

COPPA posture

COPPA applies to online services directed to children under 13. FamSpots is directed to parents, not children. We do not collect personal information from children directly. The family profile is supplied by the parent and stays scoped to that parent's account, protected by row-level security in the database.

Your rights and controls

  • Edit: update your family profile any time in Settings.
  • Export (GDPR Art. 20): download a JSON copy of everything we store about you — profile, favorites, recent picks, and usage counters — from Settings → "Download my data".
  • Delete (GDPR Art. 17 / CCPA): permanently delete your account and all associated rows from Settings → "Delete my account". This cascade removes your family profile, favorites, recent picks, usage counters, and your sign-in. It cannot be undone.

Retention

Profile, favorites, and recent picks are retained until you delete them or close your account. Daily usage counters are retained for up to 90 days for abuse prevention. Server logs (no PII, no kid data) are kept up to 30 days.

Vendor caveats

  • Google Places, Geocoding, and Place Photos are accessed through a server-side key proxy. Google's own terms (data retention, analytics) apply at their end and are outside our control.
  • AI rationale generation is provided through the Lovable AI Gateway; we send only place names and matched factor strings, no kid identifiers.
  • Auth, database, and storage are provided by Lovable Cloud. Sign-in tokens are kept in your browser's local storage to keep you signed in.

Security

Every table that stores your data uses row-level security so only your account can read or write its rows. Passwords are checked against known-breach lists at signup, and email verification is required before sign-in.

Your rights (GDPR / CCPA)

You can download everything we store about you, or permanently delete your account, at any time. Both are one click from Settings → Your data. Deletion is immediate and irreversible.

Changes & contact

If we materially change this policy, we'll surface a notice in the app before the change takes effect. Questions or data requests? Email privacy@famspots.com.